Fedora 17 : glibc-2.15-54.fc17 (2012-11508)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

Avoid unbound alloca in vfprintf (#841318)

Revert patch for BZ696143, it made it impossible to use IPV6 addresses
explicitly in getaddrinfo, which in turn broke ssh, apache and other
code. (#808147)

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=808147
https://bugzilla.redhat.com/show_bug.cgi?id=841318
http://www.nessus.org/u?49a0ea27

Solution :

Update the affected glibc package.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.5
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Fedora Local Security Checks

Nessus Plugin ID: 61556 ()

Bugtraq ID: 54374

CVE ID: CVE-2012-3405
CVE-2012-3406